SpyLoan¶ñÒâÈí¼þÔÙÏ®£º15¿îÐÂÀûÓÃGoogle PlayÏÂÔØ³¬800Íò´Î
°ä²¼¹¦·ò 2024-12-021. SpyLoan¶ñÒâÈí¼þÔÙÏ®£º15¿îÐÂÀûÓÃGoogle PlayÏÂÔØ³¬800Íò´Î
11ÔÂ30ÈÕ£¬Google Play ÉÏ·¢ÏÖÁËÒ»×éеÄ15¸öSpyLoan Android¶ñÒâÈí¼þÀûÓ÷¨Ê½£¬ÕâЩÀûÓÃÖØÒªÕë¶ÔÄÏÃÀ¡¢¶«ÄÏÑǺͷÇÖÞµÄÓû§£¬×°ÖÃÁ¿Òѳ¬¹ý800Íò´Î¡£ÕâЩÀûÓ÷¨Ê½ÓÉ¡°ÀûÓ÷¨Ê½·ÀÓùͬÃË¡±³ÉÔ±Âõ¿Ë·Æ·¢ÏÖ²¢»ã±¨£¬ËæºóÒѱ»´ÓAndroid¹Ù·½ÀûÓÃÉ̵êÖÐɾ³ý¡£SpyLoanÀûÓ÷¨Ê½ÒÔ½ðÈÚ¹¤¾ßΪ»Ï×Ó£¬Í¨¹ý¼±¾çÉóÅúÁ÷³ÌÏòÓû§ÌṩºýŪÐÔÇÒͨ³£ÐéαµÄ´û¿îÌõ¿î¡£Ò»µ©Êܺ¦Õß×°ÖÃÁËÕâЩÀûÓã¬ËûÃǾͻᱻҪÇóÌá½»Ãô¸ÐµÄÉí·ÝÖ¤Ã÷Îļþ¡¢Ô±¹¤ÐÅÏ¢ºÍÒøÐÐÕË»§Êý¾Ý£¬²¢Í¨¹ýÒ»´ÎÐÔÃÜÂë½øÐÐÑéÖ¤¡£´Ë±í£¬ÕâЩÀûÓû¹»áÀÄÓÃÉ豸ȨÏÞÍøÂç´óÁ¿Ãô¸ÐÊý¾Ý£¬Ô̺¬ÁªÏµÈËÁÐ±í¡¢¶ÌÐÅ¡¢Ïà»ú¡¢Í¨»°¼Í¼ºÍµØÎ»µÈ£¬ÓÃÓÚºóÐøµÄÀÕË÷¹ý³Ì¡£Ö»¹ÜGoogleµÄÀûÓÃÉóºË»úÔìÄܹ»ÆÁ±ÎÎ¥·´Play StoreÌõ¿î±êÈí¼þ£¬µ«SpyLoanÀûÓÃÒÀÈ»¿ÉÄÜÂ©Íø¡£ÎªÁË·À±¸ÕâÖÖ·çÏÕ£¬Óû§Ó¦×ÐϸÔĶÁÓû§ÆÀÂÛ¡¢²é³¿ª·¢ÕßµÄÃûÓþ¡¢ÏÞ¶È×°ÖÃʱÊÚÓèÀûÓ÷¨Ê½µÄȨÏÞ£¬²¢È·±£É豸ÉϵÄGoogle Play Protect´¦Óڻ״̬¡£
https://www.bleepingcomputer.com/news/security/spyloan-android-malware-on-google-play-installed-8-million-times/
2. ²©ÂåÄáÑÇ×ãÇò¾ãÀÖ²¿ÔâRansomHubÀÕË÷Èí¼þ¹¥»÷
11ÔÂ30ÈÕ£¬Òâ´óÀûÖ°Òµ×ãÇò¾ãÀÖ²¿²©ÂåÄáÑÇ×î½ü³ÉΪÁËRansomHubÍøÂç·¸×ïÍÅ»ïµÄÀÕË÷Èí¼þ¹¥»÷Ö¸±ê¡£¾Ý¸ÃÍÅ»ïÔÚ°µÍøÉϵÄÌû×Ó£¬ËûÃÇÐû³ÆÒѾÇÔÈ¡²¢°ä²¼Á˲©ÂåÄáÑǵĴóÁ¿Êý¾Ý£¬Ô̺¬Ö÷¶ÍÁ·ÎÄÉ×ô¡¤Òâ´óÀûŵµÄ¹ÍÓ¶ºÏͬ£¬ÆäÖоßÌåÁгöÁËËûµÄн³êºÍ½±½ðÐÅÏ¢¡£´Ë±í£¬»¹Ðû³ÆÇÔÈ¡ÁËǰÖúÀí¶ÍÁ·µÄ»¤ÕÕɨÃè¼þ¡¢Ò»Ïß¶ÓÇòÔ±µÄ»¤ÕÕ¡¢ºÏͬºÍÓ×ÎÒÊý¾Ý£¬ÒÔ¼°¾ãÀÖ²¿µÄ²ÆÕþÇé¿öÃ÷ϸºÍÒ½ÁÆÊý¾ÝµÈ¡£RansomHubÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉϰµÊ¾£¬²©ÂåÄáÑÇÒòÍøÂ簲ȫÐÔ²»¼°¶øÔâµ½¹¥»÷£¬Ëùº±¼û¾Ý¾ù±»µÁ¡£¾ãÀÖ²¿Ëæºó°ä·¢ÉêÃ÷֤ʵÁËÀÕË÷Èí¼þ¹¥»÷µÄ´æÔÚ£¬²¢°µÊ¾Êý¾Ý¿ÉÄܻᱻ¹«¿ª¡£RansomHub¸øÁ˲©ÂåÄáÑÇÈýÌ칦·òÀ´Âú×ãδ¹«¿ªµÄÒªÇ󣬲»È»Ëùº±¼û¾Ý½«ÓÚ11ÔÂ29ÈÕÖÐÎç¸éÖÃÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏ¡£Ö»¹Ü²©ÂåÄáÑǵȾãÀÖ²¿´ËÇ°Ò²ÔøÔâ·ê¹ýÍøÂç¹¥»÷£¬µ«Õâ´ÎÊÂÎñÔÙ´ÎÌáÐÑÁËÖ°Òµ×ãÇò¾ãÀÖ²¿¼ÓÇ¿ÍøÂ簲ȫ·À»¤µÄ³ÁÒªÐÔ¡£
https://www.theregister.com/2024/11/30/bologna_fc_ransomhub/
3. Rockstar 2FA£ºÐÂÐÍÍøÂç´¹µöƽ̨ÇÔÈ¡Microsoft 365Í´´¦
11ÔÂ29ÈÕ£¬ÃûΪ¡°Rockstar 2FA¡±µÄÐÂÐÍÍøÂç´¹µö¼´·þÎñ£¨PhaaS£©Æ½Ì¨ÒѾ³öÏÖ£¬×¨ÎªÖ´Ðдó¹æÄ£ÖÐÑëÈË£¨AiTM£©¹¥»÷¶øÉè¼Æ£¬Ö¼ÔÚÇÔÈ¡Microsoft 365Í´´¦¡£¸Ãƽ̨ͨ¹ýÀ¹½ØÓÐЧµÄ»á»°cookie£¬ÔÊÐí¹¥»÷ÕßÈÆ¹ýÖ¸±êÕÊ»§µÄ¶à³ÁÉí·ÝÑéÖ¤£¨MFA£©±£»¤¡£Êܺ¦Õß±»ÓÕµ¼µ½·ÂðµÄMicrosoft 365µÇÂ¼Ò³Ãæ£¬ÊäÈëÍ´´¦ºó£¬AiTM·þÎñÆ÷½«Æäת·¢ÖÁMicrosoftµÄºÏ·¨·þÎñʵÏÖÑéÖ¤£¬²¢ÔÚ·µ»ØÊ±²¶»ñcookie¡£Rockstar 2FAÏÖʵÉÏÊÇDadSecºÍPhoenix¹¤¾ß°üµÄ¸üа棬×Ô2024Äê8ÔÂÒÔÀ´ÔÚÍøÂç·¸×ïÉçÇøÖдóÊÜÓ½Ó£¬Á½ÖÜÊÛ¼Û200ÃÀÔª£¬API½Ó¼ûÐø¶©180ÃÀÔª¡£¸Ã·þÎñÔÚTelegramµÈÆ½Ì¨ÍÆ¹ã£¬¾ß±¸¶àÏîÖ°ÄÜ£¬ÈçÖ§³Ö¶à¸öƽ̨¡¢Ìӱܼì²â¡¢Êܺ¦Õßɸ²é¡¢×Ô¶¯FUD¸½¼þºÍÁ´½Ó¡¢Óû§¶ØÄÀµÄÖÎÀíÃæ°åµÈ¡£×Ô2024Äê5ÔÂÒÔÀ´£¬ÒѳÉÁ¢5000¶à¸öÍøÂç´¹µöÓò£¬ÀÄÓúϷ¨µç×ÓÓʼþÓªÏúƽ̨»òÈëÇÖÕË»§´«²¼¶ñÒâÐÅÏ¢£¬Ê¹ÓöþάÂë¡¢ºÏ·¨Ëõ¶Ì·þÎñÁ´½ÓºÍPDF¸½¼þµÈÌÓ±Ü×èÖ¹²½Öè¡£Ö»¹Ü·¨Âɲ¿ÃÅÒѲÉÈ¡Ðж¯½ø¹¥PhaaSƽ̨£¬µ«Rockstar 2FAµÄ³öÏֺͱ鼰Åú×¢£¬Ö»ÓÐÍøÂç·¸×ï·Ö×ÓÄÜÒԵͳɱ¾»ñÈ¡ÕâЩ¹¤¾ß£¬´ó¹æÄ£ÓÐÐ§ÍøÂç´¹µöÐж¯µÄ·çÏÕÈÔ½«³ÖÐø´æÔÚ¡£
https://www.bleepingcomputer.com/news/security/new-rockstar-2fa-phishing-service-targets-microsoft-365-accounts/
4. ÐéᲩ²ÊÀûÓÃÀûÓÃAIÉùÒôÇÔÈ¡Ãô¸ÐÊý¾Ý
11ÔÂ29ÈÕ£¬ÍøÂç·¸×ï·Ö×ÓÕýÀûÓôøÓÐAIÌìÉúÉùÒôµÄÐéᲩ²ÊÀûÓ÷¨Ê½ºÍ¸æ°×£¬Í¨¹ýÉ罻ýÌåÆ½Ì¨ÒýÓÕÓû§ÏÂÔØÚ²ÆÐÔÀûÓ㬴ӶøÇÔÈ¡Ó×ÎÒÐÅÏ¢ºÍ½ðÇ®¡£¾ÝÍøÂ簲ȫ¹«Ë¾Group-IB·¢ÏÖ£¬ÒÑÓг¬¹ý500ÌõÐéα¸æ°×ºÍ1377¸ö¶ñÒâÍøÕ¾±»¼ø±ð£¬ÖØÒªÕë¶Ô°£¼°¡¢Öж«¡¢Å·ÖÞºÍÑÇÖÞÓû§¡£ÕâЩڿÆÕßʹÓÃAIÌìÉú¶à˵»°ÉùÒô£¬Ôö³¤È¦Ì׵ĿÉÐŶȣ¬µ¼ÖÂÊܺ¦ÕßÔâ·ê³Á´ó¾¼ÃËðʧ£¬²¿ÃÅËðʧ³¬¹ý10,000ÃÀÔª¡£Óû§Ó¦Ô¤·À´Ó·Ç¹Ù·½ÆðÔ´ÏÂÔØÀûÓ㬾¯Ìè²»³ÉÐŵÄÓŻݣ¬²¢²ÉȡǿÓÐÁ¦µÄ°²È«´ëÊ©£¬ÈçʹÓÃÃÜÂëºÍË«³É·ÖÉí·ÝÑéÖ¤£¬ÒÔ·À±¸´ËÀàÍøÂçÚ¿Æ¡£´Ë±í£¬ÐéαÆÀÂÛºÍÍÆ¼öÒ²ÊÇÕâЩȦÌ׵Ĺؼü´Ù³É³É·Ö£¬Óû§Ó¦Î¬³Ö¾¯Ì裬Ïàʶ×îеÄÔÚÏßڿƺÍÍøÂç´¹µö¼¼Êõ£¬È·±£Ó×ÎÒÐÅÏ¢°²È«¡£
https://hackread.com/fake-betting-apps-ai-generated-voices-steal-data/
5. NHS¶ùͯҽԺÔâINC RansomÀÕË÷Èí¼þÍŻ﹥»÷
11ÔÂ29ÈÕ£¬Ó¢¹ú¹ú¶ÈÒ½ÁÆ·þÎñϵͳ£¨NHS£©µÄÀûÎïÆÖ°¢¶ûµÂº£¶ùͯҽԺºÍÀûÎïÆÖÐÄÐØÒ½ÔºNHS»ù½ð»áËÆºõÕýÔâ·êINC RansomÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷£¬¸ÃÍÅ»ïÍþвҪй¶ÆäËùÇÔÈ¡µÄÊý¾Ý¡£¾Ý³Æ£¬ÕâЩÊý¾ÝÔ̺¬»¼Õߺ;èÔùÕßµÄÈ«Ãû¡¢µØÖ·¡¢¾èÔù½ð¶î¡¢Ò½Áƻ㱨ºÍ²ÆÕþÎļþµÈ£¬¹¦·ò¿ç¶È´Ó2018ÄêÖÁ2024Äê¡£Ò½ÔºÒѰ䷢ÉêÃ÷£¬ÔÚÓëºÏ×÷ͬ°éºËʵÊý¾Ý²¢ÏàʶDZÔÚÓ°Ï죬ͬʱÓë¹ú¶È·¸×ï¾ÖºÏ×÷±£»¤ÏµÍ³¡£Óë´Ëͬʱ£¬µØÀíµØÎ»ÏàÁÚµÄÍþÀÕ¶ûNHSÐÅÈλú¹¹Ò²Ôâ·êÁËÍøÂç¹¥»÷£¬µ«Á½´ÎÏ®»÷ËÆºõûÓйØÁª¡£Ö»¹ÜNHS×éÖ¯Êܵ½Ï®»÷µÄÇé¿ö²¢²»º±¼û£¬µ«Á½´ÎÏ®»÷ÔÚͳһÖÜÄÚÏà¸ô²»Ô¶£¬ÊµÊôÆæ¹Ö¡£°¢¶ûµÂ¡¤ºÚÒÁÒ½Ôº°µÊ¾£¬Æä·þÎñÕý³£ÔËÐУ¬Ã»ÓÐÊܵ½Ó°Ïì¡£INC RansomÍÅ»ïÔøÏ®»÷¹ýËÕ¸ñÀ¼NHSϵͳ£¬²¢ÇÔÈ¡ÁË15ÍòÈ˵ÄÊý¾Ý£¬Õâ´ÎÏ®»÷ÊÖ·¨ÀàËÆ£¬¿ÉÄÜÊÇΪÁËÊ©¼ÓѹÁ¦ÒÔÂú×ãÀÕË÷ÒªÇó¡£
https://www.theregister.com/2024/11/29/inc_ransom_alder_hey_childrens_hospital/
6. ¶íÂÞ˹·¨Âɲ¿ÃÅÒÑ¿ÛÁô²¢¸æ×´ÍøÂç·¸×ï·Ö×ÓWazawaka
11ÔÂ29ÈÕ£¬¶íÂÞ˹·¨Âɲ¿ÃÅÒÑ¿ÛÁô²¢¸æ×´³ôÃûÔ¶ÑïµÄÀÕË÷Èí¼þ¿ª·¢ÕßÃ×¹þÒÁ¶û¡¤ÅÁ·òÂåÎ¬Ææ¡¤ÂíÌØÎ¬Ò®·ò£¨Mikhail Pavlovich Matveev£©£¬ËûÒ²±»³ÆÎªWazawaka¡¢Uhodiransomwar¡¢m1xºÍBoriselcin¡£Ëû±»Ö¸¿Ø¿ª·¢¶ñÒâÈí¼þ²¢²Î¼Ó¶à¸öºÚ¿Í×éÖ¯¡£¾Ý¶íÂÞ˹ÄÚÎñ²¿ÉêÃ÷£¬µ÷²éÈËÔ±ÒÑÍøÂçµ½×ã¹»Ö¤¾Ý£¬²¢½«ÆäÒÆËÍÖÁ¼ÓÀïÄþ¸ñÀÕÊÐÖÐÑë´¦Ëù·¨Ôº½øÐÐÉóÀí¡£ÍøÂçÕþ²ßר¼Ò°ÂÁиñ¡¤É³»ùÂå·ò·¢ÏÖ£¬ÂíÌØÎ¬Ò®·ò´òËãʹÓÃÀÕË÷Èí¼þ¼ÓÃÜóÒ××éÖ¯µÄÊý¾ÝÒÔÊÕÈ¡½âÃÜÊê½ð¡£È¥Äê5Ô£¬ÃÀ¹ú˾·¨²¿Ò²¶ÔÂíÌØÎ¬Ò®·òÌá³öÖ¸¿Ø£¬Ö¸¿ØËû²Î¼ÓÁËHiveºÍLockBitÀÕË÷Èí¼þÐж¯¡£´Ë±í£¬Ëû»¹±»ÒÔΪÊÇRampºÚ¿ÍÂÛ̳µÄ´´½¨ÕߺÍÖÎÀíÔ±£¬ÒÔ¼°BabukÀÕË÷Èí¼þÐж¯µÄ×î³õÖÎÀíÔ±¡£ÃÀ¹ú²ÆÕþ²¿±í¹ú×ʲú½ÚÔì°ì¹«ÊÒÒ²¶ÔÂíÌØÎ¬Ò®·òÖ´ÐÐÁËÔì²Ã£¬ÃÀ¹ú¹úÎñÔºÐüÉÍ1000ÍòÃÀÔªÕ÷¼¯ÓйØËûµÄÐÅÏ¢¡£ÂíÌØÎ¬Ò®·òÔÚÍøÉϷdz£»îÔ¾£¬Ê±Ê±ÓëÍøÂ簲ȫ×êÑÐÈËÔ±ºÍרҵÈËÊ¿½»Ì¸£¬²¢¹«¿ª»áÉÌËûµÄÍøÂç·¸×ï»î¶¯¡£ÔÚÊܵ½ÃÀ¹úÔì²Ãºó£¬ËûÉõÖÁÔÚÍÆÌØÉϳ°·íÃÀ¹ú·¨Âɲ¿ÃÅ£¬²¢°ä²¼ÁËÒ»ÕÅͨ¼©º£±¨µÄÕÕÆ¬¡£
https://www.bleepingcomputer.com/news/security/russia-arrests-cybercriminal-wazawaka-for-ties-with-ransomware-gangs/


¾©¹«Íø°²±¸11010802024551ºÅ